Privacy Policy
A specific policy, not a template. It describes what these tools actually do — including the parts where data does leave your browser.
The short version
- There is no analytics, no tracking pixel and no advertising network on this site. We do not know who you are or which tools you used.
- There are no tracking cookies. The site sets no cookies at all.
- Most tools run entirely in your browser. What you paste in stays on your machine.
- Some tools must contact a third party to do their job — fetching a page you asked for, or calling an AI or SERP API with your own key. Those cases are listed below, by name.
- One tool, the Domain Manager, stores your data — because that is what it is for. It needs a free Google sign-in and is covered in its own section.
Who we are
SerpHammer (serphammer.com) is operated by Abhishek Chaurasiya. For any privacy question or request, write to support@serphammer.com.
What stays in your browser
Tools use your browser's own localStorage and IndexedDB to remember things between visits. This data never reaches us — it sits on your device and you can wipe it any time by clearing site data for serphammer.com. It includes:
- Your light or dark theme choice.
- Saved lists, projects and settings inside individual tools — URL lists, keyword sets, column layouts, and so on.
- Any API key you paste into a tool (see below).
- A flag recording that you dismissed the "install this app" prompt, so it does not nag you again.
Server logs
The site is static files on shared hosting. Like every web server, the host records standard access logs — IP address, timestamp, requested URL, user agent — which are used for security and troubleshooting and are not combined with anything else or used to profile you.
Third-party services, named
This is the part most policies gloss over. These are every outside service the site can contact, and exactly when:
- Google Fonts (
fonts.googleapis.com,fonts.gstatic.com) — every page loads its typefaces from Google, so Google sees your IP address and user agent when the fonts are fetched. - Public CORS proxies —
corsproxy.io,api.allorigins.win,api.codetabs.com,r.jina.ai. A browser cannot read a page from another website directly, so tools that inspect a URL you supplied (WordPress ID Finder, Elementor Bulk Editor, Sitemap URL Extractor, Topic Suggestion) route that request through one of these. The URL you entered is visible to that proxy operator. Only public URLs are ever sent — never credentials. - SerpHammer fetch proxy (
sitemap-proxy.abhishekchaurasiya-com.workers.dev) — a Cloudflare Worker used by some tools for the same reason. It fetches the URL you asked for and passes the response back; it does not retain the content. - AI and SERP providers — Google Gemini (
generativelanguage.googleapis.com), Mistral (api.mistral.ai), Serper (google.serper.dev), ScaleSERP (api.scaleserp.com), DataForSEO (api.dataforseo.com). These are only ever called when you paste in your own API key for that provider. The key and the request go directly from your browser to them — never through us, and we never see either. Your agreement for that data is with the provider. - Google Firebase — authentication and database for the Domain Manager only. See the next section.
The Domain Manager (the one tool that stores data)
The Domain Manager exists to keep a domain portfolio across your devices, so it necessarily stores what you enter. Specifically:
- You sign in with Google through Firebase Authentication. We receive your Google account's email address, display name and profile photo URL — nothing else, and never your Google password.
- The domain records you create (domain names, registrars, expiry and renewal dates, prices, notes, status) are stored in Google Cloud Firestore under your own user ID. Security rules restrict every record to the account that created it.
- Google acts as our data processor here and holds this data on its infrastructure, subject to Google's own privacy terms.
- Deleting your data: you can delete individual domains inside the tool at any time. To have the whole account and all its records erased, email support@serphammer.com from the address you signed in with and it will be deleted.
Children
These are professional tools and are not directed at children under 13. We do not knowingly collect data from them.
Your rights
Where the GDPR, the UK GDPR, India's DPDP Act or a similar law applies to you, you have the right to access, correct, export or erase the personal data we hold, and to object to its processing. In practice we hold almost nothing — the only personal data on our side is a Domain Manager account, plus any email you have sent us. Write to support@serphammer.com and it will be handled within 30 days.
Security
The site is served over HTTPS only, with a strict Content-Security-Policy, X-Frame-Options, nosniff and HSTS. Tools escape everything they render, so a page you analyse cannot inject code into the tool. No system is perfect; if you find a security issue, please report it to support@serphammer.com before disclosing it publicly.
Changes
If a new tool changes what is collected, this page is updated and the date below changes with it. Material changes will be noted here rather than made quietly.
Last updated: 28 July 2026